ElCampeon Systems

ElCampeon Security

Security testing for web apps & APIs

Hands-on testing by a working security researcher. You get findings you can reproduce, a specific fix for each one, and a free retest once you've patched.

Illustrative example of a scope file

What we test

Manual testing, scoped to what you run

No automated scan dressed up as a pentest. A person works through your app the way an attacker would, across every role you give us.

Taking enquiries

Web application testing

Logged-in and logged-out testing of your web app, across every user role you give us.

  • Access control and privilege escalation between users and roles
  • Authentication, sessions, password reset and account takeover paths
  • Injection, cross-site scripting and server-side request forgery
  • Business logic: payments, coupons, limits and workflows
Taking enquiries

API security testing

REST and GraphQL APIs, including the private endpoints your mobile and web clients call.

  • Object- and function-level authorization (BOLA, BFLA)
  • Mass assignment and excessive data exposure
  • Token handling, rate limits and unauthenticated endpoints
  • Undocumented and forgotten endpoints found during recon
Coming 2027

AI and LLM application testing

For products built on large language models. We're training for this now, and testing our own Claude features first.

  • Direct and indirect prompt injection
  • Data leaking through tools, retrieval and system prompts
  • Agents taking actions they shouldn't
  • The ordinary web and API bugs around the model

Process

How a test runs

Claude speeds up the mapping. A person does the breaking, and reproduces every finding before it goes in your report.

  1. Scope and written authorization

    We agree targets, test accounts, timing and anything off limits. Testing starts only after you sign.

    Signed first
  2. Recon, assisted by Claude

    We map subdomains, endpoints, parameters and roles inside the agreed scope. Claude helps sort and prioritise the map so time goes to the riskiest parts.

    Claude-assisted
  3. Manual testing

    Hands-on testing of authorization, business logic and input handling. This is where the serious bugs are.

    By hand
  4. Report

    Every finding with a CVSS 3.1 severity, reproduction steps, business impact and a specific fix.

    Checked by hand
  5. Retest

    Once you've patched, we retest every finding and confirm in writing which are closed.

    Free within 30 days

The report

Written for the person who has to fix it

And for the person who has to sign off on it. Here's what one finding looks like.

FINDING EC-SAMPLE-01 · API · /api/v2/invoices/:id

Any signed-in user can read any customer's invoice

6.5 CVSS Medium
Priority: High

Reproduce

  1. Sign in as user A and open one of A's invoices: GET /api/v2/invoices/48190
  2. Change the ID to 48213, an invoice owned by user B.
  3. The API returns 200 OK with B's invoice, amount and billing details.

Impact

Invoice IDs are sequential, so any customer can read every other customer's billing data. CVSS rates it Medium; because it exposes personal data across the whole customer base, we recommend fixing it first.

Fix

- Invoice.findById(id)+ Invoice.findOne({
+   _id: id,
+   owner: req.user.id
+ })

Look the invoice up by ID and owner, and return 404 when it isn't yours.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Illustrative example, not taken from a client engagement.

  • 01A one-page summaryWhat we tested, what we found, and what to fix first.
  • 02CVSS 3.1 severityFor every finding, with priority adjusted for your business context.
  • 03Step-by-step reproductionThe exact requests and screenshots, so your team can see it for themselves.
  • 04A specific fixWhat to change in your code or configuration, not generic advice.
  • 05A free retestWithin 30 days of the report, for every finding.
  • 06A closure letterWritten confirmation of what's fixed, for your customers or auditors.

Try it

The severity scale we use

Every finding gets a CVSS 3.1 base score. Change the metrics to see how the sample finding above would score differently. Calculated in your browser; nothing is sent anywhere.

Attack vector
Attack complexity
Privileges required
User interaction
Scope
Confidentiality
Integrity
Availability

Base score

6.5

Medium

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Terms

How we work with you

Authorization
We test only what you own or control, and only after you sign a written authorization naming the targets.
Confidentiality
NDA on request. Findings go only to the contacts you name.
Your data
Test accounts, notes and evidence are deleted when the engagement ends.
Environment
Staging is preferred. Production testing only within limits we agree in advance.
Pricing
A fixed quote per engagement, after a short scoping conversation.
Location
Remote, from Maharashtra, India. Hours overlap with Europe and the Middle East.

Get a quote

Tell us what you need tested.

[email protected]
For a quote, include

The app or API to test, roughly how many endpoints or user roles it has, and when you need the report. We reply within two working days.

Who does the testing

Tanmay Patil, our founder. See the founder's background.